Stored XSS Vulnerability in WatchGuard Fireware OS (CVE-2026-13374)

Stored XSS Vulnerability in WatchGuard Fireware OS (CVE-2026-13374)

First seen 12 Aug 2026, 03:21 UTC Aigip.Ainvd.nist.gov 82% similarity 51.9

Article Content

Browse articles
ThreatCluster

A Cross-site Scripting (XSS) vulnerability, identified as CVE-2026-13374, has been discovered in WatchGuard Fireware OS, specifically within the ConnectWise Technology Integration module. This vulnerability allows for Stored XSS attacks, which can lead to unauthorized access and data manipulation. It is an additional attack vector related to CVE-2025-13937. The affected versions include Fireware OS 12.4 through 12.12, 12.5 up to 12.5.18, and 2025.1 through 2026.2. The vulnerability was published on July 2, 2026, and is currently unmitigated, posing a significant risk to users of the affected software. Security professionals are advised to monitor the situation closely and apply any forthcoming patches.

Key Points: • CVE-2026-13374 allows Stored XSS in WatchGuard Fireware OS, affecting multiple versions. • This vulnerability is linked to CVE-2025-13937, providing an additional attack vector. • Affected systems include Fireware OS versions 12.4 to 12.12 and 12.5 up to 12.5.18.

ThreatCluster AI How this analysis works

Timeline

2025-12-04
CVE-2025-13937 published
A vulnerability related to WatchGuard Fireware OS was disclosed, establishing a connection to CVE-2026-13374.
nvd.nist.gov
2026-07-02
CVE-2026-13374 published
The Stored XSS vulnerability in WatchGuard Fireware OS was officially published, affecting several versions.
nvd.nist.gov
2026-08-12
NVD updates CVE-2026-13374
The National Vulnerability Database enriched the CVE record for CVE-2026-13374, highlighting its implications.
nvd.nist.gov

Community

Browse all →

Tracked Entities in This Story